Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1302519
| From | Dan Carpenter <dan.carpenter@oracle.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [patch] mtip32xx: calling kfree() on an error pointer |
| Date | 2016-01-06 11:10 +0100 |
| Message-ID | <qNTcu-87B-11@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
If memdup_user() fails then we end up passing an ERR_PTR to kfree()
which is a bug.
Fixes: 85b4d87c9962 ('mtip32xx: don't open-code memdup_user()')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
diff --git a/drivers/block/mtip32xx/mtip32xx.c b/drivers/block/mtip32xx/mtip32xx.c
index 618c24f..15bec40 100644
--- a/drivers/block/mtip32xx/mtip32xx.c
+++ b/drivers/block/mtip32xx/mtip32xx.c
@@ -2032,6 +2032,7 @@ static int exec_drive_taskfile(struct driver_data *dd,
outbuf = memdup_user(buf + outtotal, taskout);
if (IS_ERR(outbuf)) {
err = PTR_ERR(outbuf);
+ outbuf = NULL;
goto abort;
}
outbuf_dma = pci_map_single(dd->pdev,
@@ -2049,6 +2050,7 @@ static int exec_drive_taskfile(struct driver_data *dd,
inbuf = memdup_user(buf + intotal, taskin);
if (IS_ERR(inbuf)) {
err = PTR_ERR(inbuf);
+ inbuf = NULL;
goto abort;
}
inbuf_dma = pci_map_single(dd->pdev,
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
[patch] mtip32xx: calling kfree() on an error pointer Dan Carpenter <dan.carpenter@oracle.com> - 2016-01-06 11:10 +0100
Re: [patch] mtip32xx: calling kfree() on an error pointer Al Viro <viro@ZenIV.linux.org.uk> - 2016-01-06 14:10 +0100
Re: [patch] mtip32xx: calling kfree() on an error pointer Dan Carpenter <dan.carpenter@oracle.com> - 2016-01-06 14:20 +0100
Re: [patch] mtip32xx: calling kfree() on an error pointer Al Viro <viro@ZenIV.linux.org.uk> - 2016-01-06 14:30 +0100
csiph-web